Watch
0
0
Fork
You've already forked hyperhive
0

swarm UI: delete linked accounts

Each row of an agent's linked accounts, except its own `main` matrix
account, gets a delete action. swarm-controller serves DELETE beside each
PUT (matrix-accounts/{account}, forge-accounts/{label}, github-account),
answers 404 for an account the store does not hold, refuses `main`, and
removes every version through `delete_all_versions`.

The matrix confirmation has a revoke checkbox, off by default: the
controller logs the stored token out at its homeserver first, and keeps
the account when that fails or no homeserver is stored.

The controller's policy gains `delete` on each agent's
`metadata/.../matrix/+`, `forge/+` and `github-token`, pinned in
bao-grants.nix.

Refs #4855
This commit is contained in:
atlas 2026-10-02 23:31:39 +02:00
commit bbf931207f
7 changed files with 705 additions and 35 deletions

View file

@ -365,7 +365,7 @@ let
# back before writing so a re-run keeps the value a live agent already holds
# instead of rotating it. `metadata/` is the revocation half: `delete` on
# `data/` only soft-deletes the newest version, and `+` being one path segment
# keeps this to the queue leaf alone.
# keeps this to the queue leaf alone, and each linked account to its one leaf.
# Each hive's matrix sender token (`matrix_account::hive_sender`) grants `read`
# for the same keep-if-live reason, and `+` for the same glob-only-as-last-segment reason.
#
@ -408,6 +408,18 @@ let
capabilities = ["list"]
}
path "${credentialMountPath}/metadata/swarm/agents/+/matrix/+" {
capabilities = ["delete"]
}
path "${credentialMountPath}/metadata/swarm/agents/+/forge/+" {
capabilities = ["delete"]
}
path "${credentialMountPath}/metadata/swarm/agents/+/github-token" {
capabilities = ["delete"]
}
path "${credentialMountPath}/data/swarm/hives/+/matrix/sender-token" {
capabilities = ["create", "read", "update"]
}